ShinyHunters obtained the private keys to Clop's Tor onion service
Assessment
This is the most consequential of ShinyHunters' claims: possession of Clop's onion service private keys would let the group stand up a site at Clop's exact existing onion address on its own infrastructure, as ShinyHunters itself argued ('if they kick us out it wouldn't matter at all because we control the private keys to host the same exact onion URL'). BleepingComputer independently confirmed the defacement of Clop's leak site and the initial uploaded taunt file, but states explicitly that it has not independently verified ShinyHunters' claims to have stolen server logs, source code, or the onion private keys. A reader repeating 'ShinyHunters has Clop's onion keys' as fact would be treating an unverified assertion by an extortion actor — one with a direct incentive to overstate what it holds — as established.
Where this claim appeared
ShinyHunters (via BleepingComputer) · 2026-09-19
https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/What “Unverified” means
Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.
2 of 5 · rating scale
Assessed in
ShinyHunters defaces Clop's leak site and claims its onion keys — a cybercrime feud, and what's actually confirmedThink this assessment is wrong? Report an error.